From ad970ee2f6d54e801e9b617de739da2073038436 Mon Sep 17 00:00:00 2001 From: Étienne Loks Date: Wed, 22 May 2019 13:33:26 +0200 Subject: Find basket permissions: check on own_find for own_findbasket permission --- ishtar_common/models.py | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) (limited to 'ishtar_common') diff --git a/ishtar_common/models.py b/ishtar_common/models.py index 99c4c0449..7e6b6c5fd 100644 --- a/ishtar_common/models.py +++ b/ishtar_common/models.py @@ -302,9 +302,11 @@ class OwnPerms(object): splited = action_name.split('_') action_own_name = splited[0] + '_own_' + '_'.join(splited[1:]) user = request.user + if action_own_name == "view_own_findbasket": + action_own_name = "view_own_find" return user.ishtaruser.has_right(action_name, request.session) or \ - (user.ishtaruser.has_right(action_own_name, request.session) - and self.is_own(user.ishtaruser)) + (user.ishtaruser.has_right(action_own_name, request.session) + and self.is_own(user.ishtaruser)) def is_own(self, user, alt_query_own=None): """ -- cgit v1.2.3